AS43128 - WebtasyRFC 4890 ✗RPKI ✓ 1/1ASPA -

← back to summary

All countriesHomeState of IPv6TopologySIXAboutipv6.si ↗ Sparky

AS overview

Test target: 2a02:ec:260c:9002::1 · ns1.freedns.si · address space: unknown · prefixes announced: 1

prefix(es): 2a02:ec::/32

Targets & per-vantage-point probe results (1 target(s) across 7 vantage point(s))

Source codes (hover any badge for full description): CUR=curated · NS/SOA/MX=DNS records · SPF=SPF TXT · DRV=holder-derived (www, ns1, mail, gw, …) · ATL=RIPE Atlas · PDB=PeeringDB · WHOIS=RIPE whois · RDAP=RIPE RDAP · HIT=IPv6 Hitlist · RTR=in-prefix path hop (router) · PRB=static prefix probe · SYN=synthetic prefix::1 fallback

Target IP / hostnameSourceSRB host (SOX, Belgrade)DE host (Berlin)DE host (Düsseldorf)NL host (go6lab)ITA host (Karsolink)SLO host (6connect)SLO host (T-2)
ping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reachedping1500B:80:443reached
2a02:ec:260c:9002::1
ns1.freedns.si
NSrefusedrefusedrefusedrefusedrefusedrefused??refusedrefusedrefusedrefusedrefusedrefused

SIX peering

SIX member - open peering, peering member, since 2013-09-18. IPv6 LAN: 2001:7f8:46:0:0::4:3128. Locations: lj_ijs, lj_tpl.

  • rs1-lan1-ipv6 → 2001:7f8:46::4:3128 Established (loc: lj_ijs, since 2026-09-21)
  • rs1-lan1-ipv6 → 2001:7f8:46:0:1:0:4:3128 Established (loc: lj_tpl, since 2026-09-08)
  • rs2-lan1-ipv6 → 2001:7f8:46::4:3128 Established (loc: lj_ijs, since 2026-09-08)
  • rs2-lan1-ipv6 → 2001:7f8:46:0:1:0:4:3128 Established (loc: lj_tpl, since 2026-08-24)

Announces via SIX route servers: 1 prefix(es) - 2a02:ec::/32

RPKI & ASPA

1 of 1 prefix(es) covered by a valid ROA.

PrefixRPKI stateReasonCovering VRP(s)
2a02:ec::/32✓ validmatched VRP (correct origin, length within maxLength)AS43128 /32 maxLen 48 (ripe)

Random-IP probe (yarrp) into the AS' prefixes

We probed 35 arbitrary IPv6 address(es) inside AS43128's announced prefix(es). No router inside the prefix responded. The deepest visible hop was 2001:978:2:39::a:2 at hop 14 - that router answers ICMPv6 Echo. This is not in AS43128's announced prefix; operationally it's the AS-edge / peering interface (often on a SIX peering address or an upstream's /127 link). The traceroute boundary is the AS edge: ICMPv6 Time-Exceeded responses from anything inside this AS are filtered.

ICMPv6 Type 2 (Packet Too Big) acceptance - active test

Type 2 not honored. Forged ICMPv6 PTB (MTU=1280) had no effect: the next 1500-byte Echo Reply still arrived whole (1460 B, no Fragment Header). PMTUD does not work toward this address from us.
method: ICMPv6 Echo + forged PTB, tested 2026-09-23T10:35:29Z

Failure detail - what to grep in your logs
vantageour sourceyour targetmethodresulttested (UTC)
belgrade2a09:ab81::912a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:29Z
berlin2a06:d1c1:10b::cccc2a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:29Z
duseldorf2a06:d1c1:10d::aaaa2a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:27Z
go6lab2a00:8642:42::752a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:54Z
karsolink2a12:d8c0:105a:9001::a1542a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:29Z
odin2607:fae0:a000::422a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:25Z
t22a01:261:313:b814:2a0:98ff:fe5b:13e42a02:ec:260c:9002::1icmp6-echonot_honored2026-09-23T10:35:30Z

Attempt log (belgrade):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (berlin):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (duseldorf):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (go6lab):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (karsolink):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (odin):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

Attempt log (t2):

  1. icmp6-echonot_honored (reply shrank 1460→1460 B)
  2. dns-tcpinconclusive (reply 135 B before PTB): max DNS-over-TCP segment 135B; not big enough to test PMTU shrink
  3. tlsno_tcp: TLS connect failed
  4. httpno_tcp: tcp/80 not open

To match the corresponding ICMPv6 packet on your side (host firewall, AS edge, or transit tap), look for our PTBs around the timestamps above:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a01:261:313:b814:2a0:98ff:fe5b:13e4 or src host 2a06:d1c1:10b::cccc or src host 2a06:d1c1:10d::aaaa or src host 2a09:ab81::91 or src host 2a12:d8c0:105a:9001::a154)'

If you see our PTBs arriving but the destination's TCP/Echo flow does not shrink, the drop is in the destination kernel (cause 3 below). If you don't see them at all, drop is upstream of you (cause 2). If you only see them from some of our source IPs but not others, the drop is path-asymmetric - at least one transit on the differing route is filtering.

What does "Type 2 not honored" actually mean? - click to expand

What this test does

Using the icmp6-echo method, we send a 1500-byte ICMPv6 Echo Request, then a forged ICMPv6 Type 2 (Packet Too Big) declaring path MTU=1280, and observe whether the next Echo Reply arrives split into IPv6 fragments. RFC 4890 requires hosts and intermediate networks not to filter ICMPv6 Type 2; the destination's TCP/UDP stack must act on a received PTB by lowering its Path MTU cache for that destination, which makes subsequent segments smaller.

What we measured

The TCP segment size your server emitted before our forged Type 2 was 1460 B; after, it was 1460 B. No change. RFC 4890 ("Type 2 messages MUST NOT be filtered") expects subsequent segments to shrink to fit a Path MTU of 1280 B.

Three plausible causes

  1. Your host firewall is dropping ICMPv6 Type 2 inbound. Many default firewall rule sets only allow Echo Request/Reply and Neighbor Discovery, silently dropping all other ICMPv6 types - including Packet Too Big.
  2. An upstream / transit network is dropping ICMPv6 Type 2 before it reaches you. Some transit ASes filter ICMPv6 messages other than Echo at the edge. The forged PTB never arrives, so your stack never has a chance to act on it.
  3. Your kernel is ignoring the PTB. Linux / BSD stacks normally accept ICMPv6 PTB and update the route cache, but a few sysctls (or a hardened kernel) can be configured to ignore PMTU updates - typically as part of an over-aggressive anti-spoofing or uRPF policy.

How to check & fix (Linux examples)

1. Confirm Type 2 is not blocked at the host firewall:

sudo ip6tables -L INPUT -nv | grep -iE 'icmpv6|packet-too-big'
sudo nft list ruleset 2>/dev/null | grep -A1 'icmpv6'

If you see rules dropping ICMPv6 unconditionally, change them to permit at least icmpv6 type packet-too-big (and destination-unreachable, time-exceeded, parameter-problem per RFC 4890).

2. Confirm the kernel accepts incoming PTB:

sudo sysctl net.ipv6.conf.all.accept_redirects net.ipv4.ip_no_pmtu_disc net.ipv6.route.mtu_expires

The defaults (accept_redirects=1, ip_no_pmtu_disc=0) are the right values for honoring PTB.

3. Live trace: while we have an open TCP flow with a small MSS (we run our test from 2607:fae0:a000::42 on odin, 2a00:8642:42::75 on go6lab, 2a12:d8c0:105a:9001::a154 on karsolink, 2a09:ab81::91 on belgrade, 2a01:261:313:b814:2a0:98ff:fe5b:13e4 on t2, 2a06:d1c1:10a::bbbb on amsterdam, 2a06:d1c1:10d::aaaa on duseldorf and 2a06:d1c1:10b::cccc on berlin), watch for our forged Type 2 arriving on your interface:

sudo tcpdump -i any -n -e 'icmp6 and ip6[40] = 2 and (src host 2607:fae0:a000::42 or src host 2a00:8642:42::75 or src host 2a12:d8c0:105a:9001::a154 or src host 2a09:ab81::91 or src host 2a01:261:313:b814:2a0:98ff:fe5b:13e4 or src host 2a06:d1c1:10a::bbbb or src host 2a06:d1c1:10d::aaaa or src host 2a06:d1c1:10b::cccc)'

If you see our PTBs arriving but TCP segments still stay big, the drop is in your kernel or NIC offload (cause 3). If you don't see them at all, the drop is upstream of you (cause 2) - ask your upstream(s) to permit ICMPv6 Type 2.

4. If your test target above (2026-09-23T10:35:29Z) is a host that you don't own (e.g. a third-party DNS / TLS server you happen to operate prefixes for), the verdict reflects that specific host's behaviour - try the test against a server you do own and we'll happily re-run.

RFC 4890 references: §4.3.1 (Packet Too Big - MUST NOT be dropped), and RFC 8201 for the broader PMTUD requirement.

Multi-vantage path map

Every hop of all vantages’ traceroutes toward the target, drawn left→right, grouped into per-AS bubbles (a hop seen from several vantages is one shared bubble, so converging paths merge). It answers two questions per vantage — shown on each source bubble as echo ✓/⚠/✗ · trace ✓/✗: did the destination reply to ICMPv6 Echo (✓ honored, ⚠ replied but PTB not honored, ✗ no reply), and did the traceroute reach it. A line to the target is drawn only when that vantage got an echo reply — solid if the PTB was honored, dashed if not (reachable but a broken-PMTUD / RFC 4890 violation). The path depth still shows how far the traceroute itself got, and runs of unanswered (* *) hops collapse into one dashed “silent” bubble. Open full size ↗

multi-vantage path diagram for AS43128

From SRB host (SOX, Belgrade)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 54.9ms
4/4
Echo 1500B (DF) 55.0ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a09:ab81::10.2ms0%*AS60733PERKE-NET - ZORAN PEROVIC trading as Agencija Perke.NET, RS
2sox-pn.sox.rs
2001:7f8:1e:8::3a
0.4ms0%AS13004SOX - Serbian Open Exchange DOO, RS
32001:7f8:1e:8::3d0.4ms0%AS13004SOX - Serbian Open Exchange DOO, RS
42001:67c:128c::69920.6ms0%-NA
5ns1.freedns.si
2a02:ec:260c:9002::1
54.8ms0%AS43128DHH-AS - DHH-AS, SI

tracepath -6

 1?: [LOCALHOST]                        0.010ms pmtu 1500
 1:  _gateway                                              0.611ms 
 1:  _gateway                                              0.574ms 
 2:  sox-pn.sox.rs                                         0.497ms 
 3:  2001:7f8:1e:8::3d                                     0.859ms asymm  2 
 4:  2001:67c:128c::699                                   19.778ms 
 5:  ns1.freedns.si                                       55.407ms reached
     Resume: pmtu 1500 hops 5 back 15 

From DE host (Berlin)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 32.0ms
4/4
Echo 1500B (DF) 32.0ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1xe-0-0-13-178.gw01.ber01.as59645.net
2a06:d1c1:100:b::1
0.1ms0%*AS59645WYBT-NET - Tobias Fiebig, DE
2ae0-2453.cr10.ber01.lwlcom.net
2a06:d1c0::dead:beef:1c02
0.8ms0%*AS59645WYBT-NET - Tobias Fiebig, DE
3ae0-150.cr10.fra01.lwlcom.net
2a00:c380:b200:230::174
10.1ms0%AS50629LWLCOM - LWLcom GmbH, DE
4ae0-20.cr10.fra07.lwlcom.net
2a00:c380:b200:230::31
10.2ms0%AS50629LWLCOM - LWLcom GmbH, DE
5*-50%-
6lo0.0.bar1.Ljubljana1.level3.net
2001:4c08::53
32.6ms0%AS3356LEVEL3 - Level 3 Parent, LLC, US
72001:1900:5:2:2::30e632.0ms0%AS3356LEVEL3 - Level 3 Parent, LLC, US
8*---
9ns1.freedns.si
2a02:ec:260c:9002::1
31.9ms0%AS43128DHH-AS - DHH-AS, SI

Rate-limited ICMPv6: hop 5 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.019ms pmtu 1500
 1:  xe-0-0-13-178.gw01.ber01.as59645.net                  0.668ms 
 1:  xe-0-0-13-178.gw01.ber01.as59645.net                  0.650ms 
 2:  ae0-2453.cr10.ber01.lwlcom.net                        1.145ms 
 3:  ae0-150.cr10.fra01.lwlcom.net                        10.418ms asymm  7 
 4:  ae0-20.cr10.fra07.lwlcom.net                         10.400ms asymm  6 
 5:  no reply
 6:  lo0.0.bar1.Ljubljana1.level3.net                     32.417ms asymm  7 
 7:  2001:1900:5:2:2::30e6                                32.638ms asymm  8 
 8:  no reply
 9:  ns1.freedns.si                                       32.215ms reached
     Resume: pmtu 1500 hops 9 back 10 

From DE host (Düsseldorf)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 25.9ms
4/4
Echo 1500B (DF) 25.9ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1xe-0-0-12-142.gw01.dus01.as59645.net
2a06:d1c1:100:d::1
0.1ms0%*AS59645WYBT-NET - Tobias Fiebig, DE
2eth1-0-12-h5594.edge5-dus1.bb.wiit.network
2001:4ba0:92f4:3::1
2.1ms0%AS24961MYLOC-AS - WIIT AG, DE
3lag10-h5f01.agr4-dus1.bb.wiit.network
2001:4ba0:ffe9:7c::1
14.9ms0%AS24961MYLOC-AS - WIIT AG, DE
4lag30.core3-dus1.bb.wiit.network
2001:4ba0:ffe9:109::2
0.2ms0%AS24961MYLOC-AS - WIIT AG, DE
5*-0%-
6lo0.0.bar1.Ljubljana1.level3.net
2001:4c08::53
25.8ms0%AS3356LEVEL3 - Level 3 Parent, LLC, US
72001:1900:5:2:2::30e625.9ms0%AS3356LEVEL3 - Level 3 Parent, LLC, US
8*---
9ns1.freedns.si
2a02:ec:260c:9002::1
26.1ms0%AS43128DHH-AS - DHH-AS, SI

tracepath -6

 1?: [LOCALHOST]                        0.026ms pmtu 1500
 1:  xe-0-0-12-142.gw01.dus01.as59645.net                  0.634ms 
 1:  xe-0-0-12-142.gw01.dus01.as59645.net                  0.587ms 
 2:  eth1-0-12-h5594.edge5-dus1.bb.wiit.network            1.133ms 
 3:  no reply
 4:  lag11.core3-dus1.bb.wiit.network                      0.512ms 
 5:  no reply
 6:  lo0.0.bar1.Ljubljana1.level3.net                     27.236ms 
 7:  2001:1900:5:2:2::30e6                                26.505ms 
 8:  no reply
 9:  ns1.freedns.si                                       26.474ms reached
     Resume: pmtu 1500 hops 9 back 9 

From NL host (go6lab)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 121.0ms
4/4
Echo 1500B (DF) 29.5ms
yes
Type 1 dest-unreach
-
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
12a00:8642:42::22.6ms0%AS203993GNA-DC1-AS - S.J.M. Steffann, NL
2*-0%*-
32a00:1ca8:1::19412.0ms10%AS50673Serverius-as - Serverius Holding B.V., NL
42a03:3f40::10:413.2ms0%AS50673Serverius-as - Serverius Holding B.V., NL
52001:978:2:40::3:14.1ms0%AS174COGENT-174 - Cogent Communications, LLC, US
6be3458.ccr42.ams03.atlas.cogentco.com
2001:550:0:1000::9a36:27b9
5.6ms0%AS174COGENT-174 - Cogent Communications, LLC, US
7be3343.ccr41.fra05.atlas.cogentco.com
2001:550:0:1000::9a36:3e8d
12.5ms0%AS174COGENT-174 - Cogent Communications, LLC, US
8be5516.ccr21.muc03.atlas.cogentco.com
2001:550:0:1000::9a36:3e7a
21.4ms0%AS174COGENT-174 - Cogent Communications, LLC, US
9be5456.ccr81.vie01.atlas.cogentco.com
2001:550:0:1000::9a36:48a6
25.0ms30%AS174COGENT-174 - Cogent Communications, LLC, US
10be3935.agr61.vie01.atlas.cogentco.com
2001:550:0:1000::9a36:274e
28.7ms0%AS174COGENT-174 - Cogent Communications, LLC, US
11be3189.rcr61.lju01.atlas.cogentco.com
2001:550:0:1000::9a36:4ac5
28.0ms0%AS174COGENT-174 - Cogent Communications, LLC, US
12be9462.nr61.b021176-0.lju01.atlas.cogentco.com
2001:550:0:1000::9a19:11a5
30.0ms0%AS174COGENT-174 - Cogent Communications, LLC, US
132001:978:2:39::a:229.7ms0%AS174COGENT-174 - Cogent Communications, LLC, US
14fc00:0:1f00:b000::529.1ms0%-NA
15ns1.freedns.si
2a02:ec:260c:9002::1
27.0ms0%AS43128DHH-AS - DHH-AS, SI

Rate-limited ICMPv6: hop 3, hop 9 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.041ms pmtu 1500
 1:  ???                                                 380.170ms 
 1:  ???                                                   3.872ms 
 2:  no reply
 3:  2a00:1ca8:1::194                                      2.799ms 
 4:  2a03:3f40::10:41                                      3.637ms 
 5:  2001:978:2:40::3:1                                    4.757ms 
 6:  be3457.ccr41.ams03.atlas.cogentco.com                 9.361ms 
 7:  be3343.ccr41.fra05.atlas.cogentco.com                12.548ms 
 8:  be7944.ccr22.muc03.atlas.cogentco.com                17.422ms 
 9:  be5456.ccr81.vie01.atlas.cogentco.com                23.764ms 
10:  be4080.agr62.vie01.atlas.cogentco.com                24.144ms 
11:  be9461.rcr62.lju01.atlas.cogentco.com                29.750ms 
12:  be9462.nr61.b021176-0.lju01.atlas.cogentco.com       30.621ms 
13:  2001:978:2:39::a:2                                   32.002ms 
14:  fc00:0:1f00:b000::5                                  29.002ms asymm 15 
15:  ns1.freedns.si                                       28.168ms reached
     Resume: pmtu 1500 hops 15 back 16 

From ITA host (Karsolink)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 28.7ms
4/4
Echo 1500B (DF) 39.6ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1*---
2*-0%*-
3*-50%-
42a02:2d8:4:1815:232a3.4ms0%-
5RT.IRX.FKT.DE.retn.net
2a02:2d8::57f5:e0a1
16.3ms0%AS9002RETN-AS - RETN Limited, GB
6*-0%-
7lo0.0.bar1.Ljubljana1.level3.net
2001:4c08::53
38.8ms0%AS3356LEVEL3 - Level 3 Parent, LLC, US
8port-channel5653.ccr92.mil02.atlas.cogentco.com
2001:550:0:1000::8275:2b5
10.1ms40%AS174COGENT-174 - Cogent Communications, LLC, US
9*-0%-
10ns1.freedns.si
2a02:ec:260c:9002::1
37.9ms30%AS43128DHH-AS - DHH-AS, SI

Rate-limited ICMPv6: hop 3, hop 8, hop 10 (loss between 5% and 95% across mtr cycles - the router replies but only sometimes).

tracepath -6

 1?: [LOCALHOST]                        0.028ms pmtu 1500
 1:  no reply
 2:  no reply
 3:  2a12:d8c0:109f:106::a2                                3.382ms 
 4:  2a03:b020:1:51::a                                    10.156ms 
 5:  2a03:b020::246                                       12.739ms 
 6:  2001:978:2:2a::e7:1                                  11.187ms 
 7:  lo0.0.bar1.ljubljana1.level3.net                     38.330ms 
 8:  2001:1900:5:2:2::30e6                                38.243ms 
 9:  no reply
10:  ns1.freedns.si                                       38.371ms reached
     Resume: pmtu 1500 hops 10 back 10 

From SLO host (6connect)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 1.1ms
4/4
Echo 1500B (DF) 1.1ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1fw1-lju.6connect.com
2607:fae0:a000::2
0.2ms0%*AS80386CONNECT - 6connect, Inc., US
2*---
3*-0%-
42001:7f8:46::4:3128 @SIX1.1ms0%AS51988ARNES-SIX - ARNES, SI
5fc00:0:1f00:b000::51.3ms0%-NA
6ns1.freedns.si
2a02:ec:260c:9002::1
1.3ms0%AS43128DHH-AS - DHH-AS, SI

tracepath -6

 1?: [LOCALHOST]                        0.036ms pmtu 9000
 1:  fw1-lju.6connect.com                                  0.759ms 
 1:  fw1-lju.6connect.com                                  0.714ms 
 2:  no reply
 3:  2a03:a100:0:201:1::1                                  1.020ms 
 4:  2a03:a100:0:201:1::1                                  0.833ms pmtu 1500
 4:  2001:7f8:46::4:3128                                   1.645ms 
 5:  fc00:0:1f00:b000::5                                   1.155ms 
 6:  ns1.freedns.si                                        1.308ms reached
     Resume: pmtu 1500 hops 6 back 6 

From SLO host (T-2)   openRFC 4890 ✗

filter likely at: (none) · min PMTU on path: 1500

4/4
Echo small (56B) 2.5ms
4/4
Echo 1500B (DF) 2.9ms
yes
Type 1 dest-unreach
443,80
TCP responds on

Path (traceroute + mtr + PTR)

#IP / PTRRTTmtr lossASAS holder
1*-0%*-
22a01:260:1::2251.7ms0%*AS34779T-2-AS - T-2, d.o.o., SI
32a01-260-1-1--9c.core6.t-2.net
2a01:260:1:1::9c
2.1ms0%*AS34779T-2-AS - T-2, d.o.o., SI
4six2.dhh.si @SIX
2001:7f8:46:0:1:0:4:3128
2.6ms0%AS51988ARNES-SIX - ARNES, SI
5*---
6ns1.freedns.si
2a02:ec:260c:9002::1
2.4ms0%AS43128DHH-AS - DHH-AS, SI

tracepath -6

 1?: [LOCALHOST]                        0.025ms pmtu 1500
 1:  no reply
 2:  2a01:260:1::225                                       7.837ms 
 3:  2a01-260-1-1--9a.core6.t-2.net                        2.653ms 
 4:  2001:7f8:46::4:3128                                   2.436ms 
 5:  no reply
 6:  ns1.freedns.si                                        2.957ms reached
     Resume: pmtu 1500 hops 6 back 6